1. Get acme.sh
curl https://get.acme.sh | sh
Installation successful as shown below:
... [Tue Sep 24 18:23:55 CST 2019] Good, bash is found, so change the shebang to use bash as preferred. [Tue Sep 24 18:23:55 CST 2019] OK [Tue Sep 24 18:23:55 CST 2019] Install success!
2. Get the certificate
acme.shThe powerful part is that it can automatically configure DNS, so we don't need to go to the domain backend to operate resolution records.
Here we take a domain registered at Alibaba as an example. For domains registered elsewhere, please refer to this and modify accordingly:Portal。
Please first go to the Alibaba Cloud backend to getApp_KeyFollowApp_Secret Portal, then execute the following script
# 替换成从阿里云后台获取的密钥 export Ali_Key="123" export Ali_Secret="abbcddddd" # 换成自己的域名 acme.sh --issue --dns dns_ali -d example.com -d *.example.com
After successful execution, the output is:
... [Tue Sep 24 18:28:45 CST 2019] Download cert, Le_LinkCert: https://acme-v02.api.letsencrypt.org/acme/cert/03324bb19fec1de831b1083a9810ccdd2109 [Tue Sep 24 18:28:47 CST 2019] Cert success. ...
The output information includes the directory where the certificate is stored.
The certificate generated on my side is placed in this directory:/www/server/panel/vhost/cert/example.com/example.com.cer。
After the first success, acme.sh will record the App_Key and App_Secret, and generate a scheduled task. Throughcrontab -eYou can see this command. If not needed, we can delete the scheduled task and clean up the ~/.acme.sh folder.
Note: Some domestic vendors may require content in pem format. Just copy the contents of the following two certificates (cer === PEM):
Certificate content (PEM format):
$ cat domain.cerCertificate private key (PEM format):
$ cat domain.key